Security
Use HTTPS for every production request and treat API keys like passwords.
Key handling
- Store keys in a server-side secret manager or protected environment variable.
- Never embed keys in browser or mobile application code.
- Never commit keys to source control or include them in logs.
- Use separate keys for separate systems and rotate a key after suspected exposure.
Tenant isolation
API keys are linked to a merchant and restricted by scopes. Order, customer, reward, card, and issued-voucher queries all include the authenticated merchant boundary, so another merchant's resource identifier is not sufficient to access or change it.
Sensitive responses
Customer, reward, order, and voucher responses can contain names, email addresses, purchase references, and loyalty activity. Only retain this data where your integration needs it, restrict internal access, and follow applicable privacy requirements.
Write safety
Use an Idempotency-Key for writes and retain the returned operation or resource identifiers for reconciliation. Do not include secrets or personal data in an idempotency key. Balance adjustments and cancellations require an audit reason; use a concise operational reference rather than unnecessary customer information.